GHSA-59h8-w5q6-mfmpMedium· 5.3▾ SunlitTrigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The POST handler for /realtime/v1/streams/:runId/:streamId has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream.
File: apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts
The action handler (line 17) has no auth wrapper. The code comment says: "Plain action for backwards compatibility with older clients that don't send auth headers."
The run lookup at line 29 uses where: { friendlyId: runId } with NO environment scoping (runtimeEnvironmentId is not checked), so production runs are accessible.
Run friendlyIds follow predictable patterns (e.g., run_1234abcd).
# No authentication required
curl -X POST "http://localhost:8030/realtime/v1/streams/run_KNOWN_ID/stream_1" -H "Content-Type: application/json" -d '{"injected": "data"}'
Unauthenticated data injection into any run realtime stream. Cross-environment access (no scoping).
trigger.dev <= 4.5.4Upgrade to a patched release:
trigger.dev 4.5.5Connected by shared product, vendor, weakness, or advisory.
GHSA-q567-cr4x-96w4Medium· 5.4Trigger.dev: Blind SSRF via alert-channel webhook
GHSA-pp95-gc86-jq6qHigh· 7.1Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
GHSA-gg6r-gp4c-89hpCriticalTrigger.dev: V1 coordinator default-secret unauth Socket.IO
GHSA-4672-hwv6-gq62Medium· 5.4Trigger.dev: Cross-environment deployment cancel
GHSA-9q4r-4842-93vwHigh· 7.7Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
GHSA-pqxw-g93w-hj9xHighTrigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise